Data Protection – Waterworld Croatia

Personal data
Personal data are all data relating to an individual whose identity has been established or can be established, and an individual or respondent whose identity can be established is a person who can be identified directly or indirectly.

Statement on the collection and use of personal data
Waterworld Croatia processes personal data in accordance with applicable regulations and acts in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data. Directive 95/46 / EC (General Data Protection Regulation – GDPR) and other regulations governing the protection of personal data.

Waterworld Croatia protects personal data of customers by collecting only the necessary, basic data on customers / users that are necessary to fulfill the obligations of the merchant; informs customers about how to use the collected data and gives customers the opportunity to choose about the use of their data. All user data is strictly kept and is available only to employees who have the authority to access and process personal customer data and who need this data to do business.

This policy applies to all users and customers of the website and online store.

Data collection
Waterworld Croatia collects only personal data that the customer enters independently. Data are collected by registering for the use of the web shop, or by filling out an electronic form for online ordering. Data collection is necessary for the provision of web shop services and services and they are collected based on the terms of use.

By creating and managing an account, data is collected: name and surname, e-mail address, username, telephone number, street and house number, postal code and city, country. By filling out the electronic order form, data is collected: name and surname, e-mail address, telephone number, street and house number, postal code and city, country.

Data processing
Processing refers to any procedure or set of procedures performed on personal data or on sets of personal data, whether automated or non-automated means such as collecting, recording, organizing, structuring, storing, adapting or modifying, finding, inspecting, using, detection by transfer, dissemination or otherwise making available, harmonization or combination, restriction, deletion or destruction.

The information collected during the creation of the user account, ie by filling in the electronic order form on the web shop is used in the following ways:

The username is used to identify the user and re-access the registered profile in the online store
The e-mail address is used to contact the customer in case of unfinished purchase of the product, send notifications about the availability of the product, notification of the received order and notification of the sent package
Name, surname, e-mail address, telephone number, postal code, place and address are used to process and track the order, including delivery of the product to the specified address
Name, surname, e-mail address, telephone number are used to manage disagreements regarding the purchase
Duration of data management
When buying products in the web shop, we keep the customer’s personal data for 6 months from the issuance of the invoice.

Invoice information is retained for 11 years from the date of invoice issuance.

Due to the better user experience and easier use of the online store, the above data is stored for registered users as long as their user profile exists on the web shop.

In the event that a registered user or customer does not want Waterworld Croatia to process data in any other way and requests the deletion of data about the same, he must notify Waterworld Croatia via e-mail to:

Waterworld Croatia does not collect special categories of personal data and requests that customers do not send or disclose information included in special categories of personal data (such as data on race or ethnicity, data on political, religious and other beliefs, health) , criminal history or trade union membership).

Freedom of choice
The personal data provided by the customer to the company is controlled by himself. If he chooses not to give his data to companies, then he will not have access to certain websites in the online store.

If the customer’s personal data changes (e-mail address, postal address, telephone number), he can notify the trader of the changes by e-mail:

Purpose and insight
Personal data are used exclusively for the aforementioned purposes and some of them will be available to external executors in the processing process.

Cardholder’s personal data protection protection statement
Wateroworld Croatia uses WSPay ™ for online payments.

WSPay siguran is a secure system for online payment, real-time payment, credit and debit cards and other payment methods. WSPay provides the customer and merchant with secure registration and transfer of entered card data, which is confirmed by the PCI DSS certificate that WSPay has. WSPay ™ uses SSL certificate 256 bit encryption and TLS 1.2 cryptographic protocol as the highest levels of protection when writing and transferring data.

WSPay ™, as the executor of credit card authorization and collection, handles personal data as a processor and treats personal data in accordance with the General Data Protection Regulation of the European Parliament and the Council No. 2016/679 and strict PCI DSS L1 rules on data protection and data transmission.

WSPay ™ uses SSL certificate 256 bit encryption and TLS 1.2 cryptographic protocol as the highest levels of protection when writing and transferring data.

Personal data used for the purpose of authorization and collection, ie in the performance of obligations under the Agreement or under the Agreement, are considered confidential data.

The following personal data of the buyer are required for the execution of the Contract (authorizations and collection):

Name and surname





Zip code


Card type

Card number

Card life

CVV card code

WSPay does not process or use this personal data except for the purpose of enforcing the authorization and collection agreement.

WSPay ™ guarantees the fulfillment of all conditions set by the applicable regulations on personal data protection for personal data processors, and in particular the taking of all necessary technical, organizational and security measures, and this is especially confirmed by the PCI DSS L1 certificate.

Waterworld Croatia has no insight into the customer’s bank details. Waterworld Croatia employees do not have access to the customer’s card number at any time. Only the number of the authorized transaction is available to them, which allows the collection of the full or partial amount of the agreed transaction or cancellation for reasons agreed with the buyer.

The protection of personal data is in line with the General Data Protection Regulation of the European Parliament and of the Council No. 2016/679-Regulation and the implementation of the General Data Protection Regulation.